diff --git a/.buildkite/pipeline.yml b/.buildkite/pipeline.yml index 2d112e1..0e462bb 100644 --- a/.buildkite/pipeline.yml +++ b/.buildkite/pipeline.yml @@ -3,17 +3,24 @@ # via nixbuild.net when cluster secrets are present. # # Artifacts: -# - APK: result-android/sleek.apk -# - Flatpak: uk.nandi.sleek.flatpak (from nix2flatpak; no naked ELF) +# - APK: result-android/sleek.apk (streamed via nix store cat) +# - Flatpak: uk.nandi.sleek.flatpak (streamed; no full closure nix copy) # # Secrets (Buildkite cluster → Secrets, org nandi / Default cluster): # - NIXBUILD_TOKEN (preferred) — soft-loaded; skip artifacts if missing # - OPENBAO_TOKEN (optional) — fetch-openbao-env.sh → NIXBUILD_TOKEN # UI: https://buildkite.com/organizations/nandi/clusters → Default cluster → Secrets +# Pipeline: https://buildkite.com/nandi/sleek # # Pipeline repository (Buildkite): Radicle Garden clone URL # https://nandi.radicle.garden/z9mjPzpVK472QXaaP1picc5U9xBR.git # RID rad:z9mjPzpVK472QXaaP1picc5U9xBR (not GitHub — baogui-shaped). +# +# Path deps (android/Cargo.toml → ../../vidya, ../../freeq/freeq-sdk) come from +# flake.lock via scripts/sync-flake-path-deps.sh (vidya: Radicle Garden; freeq: +# GitHub). Check runs in `nix develop` so mold + egui/pipewire libs + rustc come +# from the flake (same as local AGENTS.md), not apt/rustup. +# # Agents must reach nandi.radicle.garden (sleek + vidya RIDs), # github.com/codegod100/freeq, and Flathub when building Flatpak. # Hosted queue: auto (LINUX_AMD64_2X4). Use $$ so Buildkite does not interpolate @@ -28,52 +35,72 @@ env: steps: - label: ":rust: Check" key: check + timeout_in_minutes: 120 command: | set -euo pipefail - # Path deps: vidya + freeq live next to this checkout. - # Prefer flake.lock pins (vidya from Radicle Garden) when nix is available. - parent="$$(dirname "$$PWD")" - vidya_dir="$$parent/vidya" - freeq_dir="$$parent/freeq" - if [[ ! -d "$$vidya_dir/.git" && ! -f "$$vidya_dir/Cargo.toml" ]]; then - if command -v nix >/dev/null 2>&1 && [[ -f flake.lock ]]; then - bash scripts/sync-flake-path-deps.sh vidya - else - git clone --depth 1 \ - https://nandi.radicle.garden/z2UqGTRH21s3pHnJgSuMwRaPPNNcW.git \ - "$$vidya_dir" - fi - fi - if [[ ! -d "$$freeq_dir/.git" && ! -f "$$freeq_dir/freeq-sdk/Cargo.toml" ]]; then - git clone --depth 1 https://github.com/codegod100/freeq.git "$$freeq_dir" + if command -v apt-get >/dev/null 2>&1; then + sudo DEBIAN_FRONTEND=noninteractive apt-get update + sudo DEBIAN_FRONTEND=noninteractive apt-get install -y jq git patch curl ca-certificates fi + command -v jq >/dev/null 2>&1 || { + echo "jq required to read flake.lock path-dep pins" >&2 + exit 1 + } - if ! command -v rustup >/dev/null 2>&1; then - curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs \ - | sh -s -- -y --default-toolchain 1.85 + # Nix + flake shell: mold (.cargo/config.toml), rustc, libclang, pipewire, … + if ! command -v nix >/dev/null 2>&1; then + curl --proto '=https' --tlsv1.2 -sSf -L \ + https://install.determinate.systems/nix \ + | sh -s -- install linux --no-confirm --init none # shellcheck disable=SC1091 - source "$$HOME/.cargo/env" + . /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh || true + export PATH="/nix/var/nix/profiles/default/bin:$$PATH" + fi + command -v nix >/dev/null 2>&1 || { + echo "nix not on PATH after install" >&2 + exit 1 + } + if [[ ! -S /nix/var/nix/daemon-socket/socket ]]; then + sudo /nix/var/nix/profiles/default/bin/nix daemon >/tmp/nix-daemon-check.log 2>&1 & + for _ in $$(seq 1 30); do + [[ -S /nix/var/nix/daemon-socket/socket ]] && break + sleep 1 + done fi - rustup toolchain install 1.85 --profile minimal --component clippy - rustup default 1.85 - if command -v apt-get >/dev/null 2>&1; then - sudo apt-get update - sudo apt-get install -y \ - libxkbcommon-dev libxkbcommon-x11-dev \ - libwayland-dev libx11-dev libxcursor-dev libxi-dev libxrandr-dev \ - libgl1-mesa-dev libegl1-mesa-dev libvulkan-dev \ - libclang-dev pkg-config + # Flake nixConfig (cachix substituter) must not prompt (y/N) on agents. + # Match GHA / ci-nixbuild.sh; also drain stdin so a TTY cannot block. + sudo mkdir -p /etc/nix + if ! sudo grep -q 'accept-flake-config' /etc/nix/nix.conf 2>/dev/null; then + echo 'accept-flake-config = true' | sudo tee -a /etc/nix/nix.conf >/dev/null fi + export NIX_CONFIG=$$'experimental-features = nix-command flakes\naccept-flake-config = true' - cargo clippy --manifest-path host/Cargo.toml -- -D warnings - cargo test --manifest-path android/Cargo.toml --lib + # Path deps: materialize flake.lock pins (vidya Radicle + freeq GitHub). + bash scripts/sync-flake-path-deps.sh + parent="$$(dirname "$$PWD")" + [[ -f "$$parent/vidya/Cargo.toml" ]] || { echo "vidya Cargo.toml missing" >&2; exit 1; } + [[ -f "$$parent/freeq/freeq-sdk/Cargo.toml" ]] || { + echo "freeq-sdk Cargo.toml missing" >&2 + exit 1 + } - - label: ":android: APK + Flatpak (nixbuild.net)" - key: artifacts + echo "--- :nix: develop (mold + rustc from flake)" + nix develop --option accept-flake-config true --command bash -lc ' + set -euo pipefail + command -v mold >/dev/null + rustc --version + cargo --version + cargo clippy --manifest-path host/Cargo.toml -- -D warnings + cargo test --manifest-path android/Cargo.toml --lib + ' &2 + exit 1 + } + # shellcheck disable=SC1090 + source "$$setup_env" + + # Stream the .flatpak bundle only. Full `nix copy` of the flatpak out + # pulls multi‑GiB GNOME/runtime closure and OOMs LINUX_AMD64_2X4 agents. + ./scripts/ci-nixbuild.sh remote-build ".#flatpak" result-flatpak \ + uk.nandi.sleek.flatpak + bundle="result-flatpak/uk.nandi.sleek.flatpak" + [[ -s "$$bundle" ]] || { echo "Flatpak bundle missing under result-flatpak/" >&2 ls -lah result-flatpak >&2 || true exit 1 diff --git a/.cursor/skills/configure-buildkite/references/baogui-patterns.md b/.cursor/skills/configure-buildkite/references/baogui-patterns.md index 5275832..f2b0494 100644 --- a/.cursor/skills/configure-buildkite/references/baogui-patterns.md +++ b/.cursor/skills/configure-buildkite/references/baogui-patterns.md @@ -13,10 +13,13 @@ check (cargo clippy + test) ## Check step essentials -- Clone sibling `vidya` next to the checkout if missing (`dirname $PWD/vidya`). -- Install rustup toolchain **1.85** + clippy when absent. -- Install egui system libs via apt when available. -- `cargo clippy -- -D warnings` then `cargo test`. +- Materialize sibling path deps with `scripts/sync-flake-path-deps.sh` (flake.lock + pins: vidya from Radicle Garden, freeq from GitHub). Do not clone floating tips. +- Prefer **`nix develop --command …`** so mold (`.cargo/config.toml`), rustc, + and native libs come from the flake — same as local AGENTS.md. Avoid apt + mold / rustup when the flake already provides them. +- Set `accept-flake-config` non-interactively (`/etc/nix/nix.conf` + `NIX_CONFIG`). +- `cargo clippy -- -D warnings` then `cargo test` inside the flake shell. ## Flatpak step essentials diff --git a/AGENTS.md b/AGENTS.md index e2a6155..4bcd77d 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -93,7 +93,10 @@ API token is `BUILDKITE_API_KEY` in OpenBao (same KV). Agent skill: patches live under OpenBao `secret/data/radicle`. Cluster secrets (soft-loaded; artifacts skip if missing): `NIXBUILD_TOKEN` -and/or `OPENBAO_TOKEN`. Helper: `scripts/ci-nixbuild.sh`. +and/or `OPENBAO_TOKEN`. Scope `NIXBUILD_TOKEN` to `pipeline_slug: sleek` (and +`baogui-aopjch`). Helper: `scripts/ci-nixbuild.sh`. Check materializes flake.lock– +pinned `vidya`/`freeq` via `scripts/sync-flake-path-deps.sh` and runs `cargo` +inside `nix develop` (mold + libs from the flake, not apt). ```bash eval "$(./scripts/configure-buildkite-from-openbao.sh)" diff --git a/scripts/ci-nixbuild.sh b/scripts/ci-nixbuild.sh index 40bdfa8..a1c1ad0 100755 --- a/scripts/ci-nixbuild.sh +++ b/scripts/ci-nixbuild.sh @@ -6,9 +6,13 @@ # Writes an env file path on stdout as NIXBUILD_CREDS_ENV=... # and SKIP=0|1. Never prints the token. # setup Install/configure Nix + SSH to eu.nixbuild.net; requires token. -# remote-build ATTR [OUT_LINK] -# nix build ATTR on ssh-ng://nixbuild (→ eu.nixbuild.net), -# copy result locally, symlink OUT_LINK (default: result). +# remote-build ATTR [OUT_LINK] [ARTIFACT_REL …] +# nix build ATTR on ssh-ng://nixbuild (→ eu.nixbuild.net). +# If ARTIFACT_REL args are given, stream those files out of +# the remote store path with `nix store cat` (no full closure +# copy — flatpak outs reference multi‑GiB runtimes that OOM +# hosted 2x4 agents). Otherwise `nix copy` the out path and +# symlink OUT_LINK (default: result). # # Env: # NIXBUILD_TOKEN / NIXBUILDNET_TOKEN — auth token (never logged) @@ -243,6 +247,8 @@ setup_nixbuild() { remote_build() { local attr="${1:?flake attr required, e.g. .#android}" local out_link="${2:-result}" + shift 2 || true + local -a artifacts=("$@") : "${NIX_SSHOPTS:?run setup first (NIX_SSHOPTS unset)}" # Recommended remote-store path (docs.nixbuild.net/remote-builds): @@ -265,6 +271,27 @@ remote_build() { cat "$out_json" >&2 || true exit 1 } + + if [[ ${#artifacts[@]} -gt 0 ]]; then + # Stream named files from the remote out path — avoids `nix copy` of the + # full runtime closure (OOM on Buildkite LINUX_AMD64_2X4). + mkdir -p "$out_link" + local rel dest + for rel in "${artifacts[@]}"; do + dest="$out_link/$rel" + mkdir -p "$(dirname "$dest")" + echo "Streaming $out_path/$rel → $dest (nix store cat, no closure copy)" + nix store cat --store "$store_uri" "$out_path/$rel" >"$dest" + [[ -s "$dest" ]] || { + echo "empty/missing artifact after store cat: $dest" >&2 + exit 1 + } + ls -lh "$dest" + done + echo "out_link=$out_link (streamed from $out_path)" + return 0 + fi + echo "Copying $out_path from nixbuild → local store" nix copy --from "$store_uri" "$out_path" ln -sfn "$out_path" "$out_link"